C3EL logo

C3EL

Senior Information System Security Officer (ISSO) at C3EL

Washington, D.C.Full-timeCybersecurityPosted about 1 month ago
Apply with Pipeline

About the Role

<h3 class="iCIMS_InfoMsg iCIMS_InfoField_Job">**CONTINGENT UPON CONTRACT AWARD**</h3> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Overview:</h2> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text"> <p><strong>Job Title:</strong> Senior Information System Security Officer (ISSO)</p> <p><strong>Security Clearance:</strong> Ability to Obtain Tier 4 High-Risk Public Trust</p> <p><strong>Location</strong>: Washington, D.C.</p> <p><strong><em>(Due to the nature of the work and contract requirements, U.S. Citizenship is&nbsp;required.</em></strong>)</p> <p>&nbsp;</p> </div> </div> </div> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Description:</h2> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text"> <p>C3EL is seeking a Senior Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract. This role will serve as Operational Specialist for Splunk, ServiceNow, ConMon, vulnerability management, POA&amp;M, and incident and change coordination, as well as being workstream lead and secondary backup for Lead ISSO duties.&nbsp;</p> <p><strong>Responsibilities will include, but not be limited to:</strong></p> <ul> <li>Provide on-site cybersecurity and RMF sustainment support.</li> <li>Maintain traceability between ServiceNow remediation tickets and CSAM POA&amp;M records.</li> <li>Analyze findings, validate false positives, and prioritize remediation using CVSS, CISA KEV, exposure, exploitability, and mission impact.</li> <li>Support notification, triage, CSAM context retrieval, Splunk verification, SitReps, RCA, corrective actions, and post-incident updates.</li> <li>Support CAB/CCB/ERB reviews, security impact analysis, artifact updates, and post-change verification.</li> <li>Track audit, penetration-test, and assessment findings through corrective action and evidence-supported closure.</li> <li>Maintain incident-response plans and support tabletop or functional exercises.</li> <li>Produce accurate, concise, and audit-ready Government cybersecurity documentation.</li> <li>Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.</li> </ul> <p>&nbsp;</p> <h2>&nbsp;Minimum Qualifications:</h2> </div> </div> </div> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text"> <ul> <li>U.S. Citizenship.</li> <li>Eligibility to obtain a Tier 4 High-Risk Public Trust.</li> <li>Minimum seven (7) years of cybersecurity.</li> <li>Minimum five (5) years in federal ISSO, ConMon, vulnerability, security operations, or compliance work.</li> <li>Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.</li> <li>Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms.</li> <li>Direct experience with Splunk searches, dashboards, ingestion verification, log coverage, and incident timeline support.</li> <li>Direct experience with ServiceNow incidents, problems, changes, remediation tickets, and reporting.</li> <li>Direct experience with Tenable Nessus, Qualys, ACAS, or comparable Government-approved scanners.</li> <li>Experience with Defender, Intune, BigFix, or equivalent endpoint and configuration platforms.</li> </ul> <p>&nbsp;</p> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Preferred Qualifications:</h2> <ul> <li>At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.</li> </ul> <p>&nbsp;</p> </div> </div> </div> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Education:</h2> <ul> <li>Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)</li> </ul>